Security Officer

Also: Chief Information Security Officer, CISO

PCIComplianceHubLast updated

The person with primary responsibility for an entity's security. PCI DSS does not require a particular title, but it does require that responsibility for the security programme is formally assigned and, for service providers, that executive management establishes it.

Applies to. Every entity, through 12.1.4; service providers additionally through 12.4.1.
Example. A retailer names its head of IT as the person responsible for information security in its policy (12.1.4). A payment processor's board minutes record that executive management has established responsibility for protecting cardholder data and for the PCI DSS compliance programme (12.4.1), including a charter for the programme and communication to executive management.
Limits. Naming a security officer does not transfer the entity's obligations to that person; it makes someone accountable for them inside the entity. 12.1.4 asks for the assignment to be formal, which usually means the policy, and for the person to be a member of executive management or to report to one. The same requirement set assigns the day-to-day responsibilities in 12.1.3.
In PCI DSS v4.0.1. 12.1.4, 12.4.1